In October 2023, TSTT—the state-owned telecoms provider behind bmobile and Amplia—became the centre of what Prime Minister Keith Rowley would later call a national security threat. A ransomware group called RansomEXX claimed responsibility, and within weeks, personal data belonging to somewhere between 800,000 and 1.2 million customers was sitting on the dark web.
This wasn't some abstract overseas headline. It happened here, to a company most of us interact with. And the details that emerged afterwards offer a blueprint—both of how modern attacks unfold and of what any Trinidad and Tobago business can do differently.
What actually happened
TSTT initially reported the incident as occurring on 9 October 2023. But forensic work by the Check Point Incident Response Team later revealed something more troubling: the attackers had actually gained access as early as 3 October. That's roughly a week of dwell time—a week where intruders moved through systems, created accounts, and gathered what they needed before anyone noticed.
On 28 October, RansomEXX published a CSV file on the dark web. It contained full names, email addresses, national identification numbers and contact details. The reported number of affected individuals ranged from over 800,000 to approximately 1.2 million, depending on the source.
How the attackers got in
According to Trinidad Express reporting, the entry point was a compromised administrator account. Once inside, the attackers didn't sit still. They created multiple rogue accounts to widen their foothold and maintain access even if one account was discovered.
Reporting also indicates an external device was used to reach TSTT's GitLab platform. The exfiltrated material included credentials for Google Drive, Oracle servers and GitLab projects—essentially, keys to other doors.
At parliamentary hearings, management initially attributed the breach to an external dealer-channel network. But internal reporting confirmed that a compromised TSTT administrator account was the primary vector. The discrepancy didn't go unnoticed.
What was taken, and what followed
Around 6 GB of data was exfiltrated. That might not sound like much—until you realise how many personal records fit into a well-structured database export.
TSTT's initial public statement said there had been no loss or compromise of customer data. When the dark-web publication made that position untenable, the company acknowledged the exfiltration but said the data came from an outdated, decommissioned system. They maintained that no passwords or financial information were affected.
The handling of the disclosure drew heavy public criticism. CEO Lisa Agard subsequently departed. Prime Minister Rowley—whose own identification details were reportedly among the records—described it as a national security threat.
Why this matters for every business in Trinidad and Tobago
Here's the uncomfortable truth: Trinidad and Tobago has no mandatory data breach notification law. Companies aren't legally required to inform regulators or affected individuals within any set timeframe. The TSTT incident fuelled calls for stronger data protection legislation and for TT-CSIRT to be properly empowered—but as of now, those gaps remain.
TSTT wasn't alone in 2023. The Office of the Attorney General and Ministry of Legal Affairs suffered a cyber attack in July 2023 that caused outages and disrupted court operations for several weeks. Then on 26 December 2023, the National Insurance Board was hit by ransomware, closing offices for several days while they worked with TT-CSIRT.
If you're running a 50-person company thinking "we're too small to be a target"—that's exactly the logic attackers count on. Large organisations have dedicated security teams. Smaller firms often don't, which makes them easier to breach and sometimes a stepping stone to bigger targets in their supply chain.
Where IT365 fits into that attack chain
Let's walk through the TSTT breach step by step and look at where different controls might have changed the picture. This isn't about claiming any solution would definitely have stopped this attack—nobody can honestly promise that. But understanding which capabilities address which stages helps you think about your own gaps.
Step 1: The compromised administrator credentials
The attack started with valid credentials. How did the attackers get them? We don't know for certain, but the usual suspects are phishing, credential stuffing from previous breaches, or social engineering.
IT365 Managed Services addresses this stage in three ways. Dark-web monitoring watches for your organisation's credentials appearing in breach dumps—so you'd know if an admin's email and password were circulating before attackers tried them. Security awareness training and phishing testing reduce the odds of staff handing over credentials in the first place. And advanced email security blocks the phishing and business-email-compromise attempts that commonly harvest them.
None of these is a guarantee. But they're designed to make that first step harder.
Step 2: Rogue accounts created, foothold widened
Once inside, the attackers didn't just poke around. They created multiple accounts—classic persistence behaviour. They wanted to survive even if their original access was revoked.
This is where endpoint detection and response (EDR) and ransomware detection come in. These tools watch for suspicious behaviour on devices: unusual account creation, lateral movement, privilege escalation. IT365 Endpoint includes EDR with managed detection and response (MDR) as standard. That means there are actual analysts reviewing alerts, not just software generating notifications that pile up unread.
Step 3: Roughly a week of undetected dwell time
This is the part that should concern every business owner. The attackers were inside for about a week before TSTT registered an incident. A week is plenty of time to map a network, find the valuable data, and prepare for exfiltration.
The difference between having security software and having a managed service is that someone is actually watching. MDR included as standard with IT365 means Blue Chip Technologies Ltd. coordinates monitoring and response. When something looks wrong at 2am on a Saturday, there's a process for catching it—not just an alert waiting in a queue until Monday.
Step 4: Exfiltration of credentials and data from connected platforms
The attackers reached GitLab, Google Drive, and Oracle servers. They pulled credentials that could unlock even more.
IT365 User includes SaaS controls for cloud applications, plus backup for Microsoft 365 and Google Workspace. IT365 Endpoint includes endpoint backup. These don't prevent exfiltration on their own, but they limit what can be reached through compromised endpoints and ensure you can recover if data is encrypted or destroyed.
Step 5: An outdated, decommissioned system still holding live customer data
This detail stuck with me. TSTT said the exfiltrated data came from an old, decommissioned system. But "decommissioned" apparently didn't mean "wiped and disconnected." It meant "forgotten but still accessible."
Remote monitoring and management (RMM) through IT365 Endpoint gives you an accurate, maintained inventory of what you're actually running. Patching keeps those systems current. Together, they help ensure forgotten systems don't sit in the dark, holding sensitive data nobody remembers is there.
What to do this month
Regardless of who you work with for IT, here's a practical checklist any T&T business can act on:
Know what systems hold customer data. Actually document it. Include old systems, test environments, and that server in the corner nobody's touched in two years.
Retire and wipe decommissioned systems properly. If it's not in use, it shouldn't be accessible—and it definitely shouldn't hold live data.
Enforce MFA on all administrator accounts. Not optional. Not "we'll get to it." Now.
Monitor for exposed credentials. Dark-web monitoring services exist for this. Use one.
Test your restores. Backups you've never tested aren't backups. They're hopes.
Agree who to call at 2am. If something happens on a Saturday night, who's responsible? What's the escalation path?
Know TT-CSIRT exists. The Trinidad and Tobago Cyber Security Incident Response Team is a national resource. Save their contact information before you need it.
Moving forward
The TSTT breach wasn't a failure of one thing. It was a chain: credentials compromised, access maintained, dwell time undetected, data exfiltrated, disclosure delayed. Each link offered an opportunity to interrupt the attack. Each link that held made the next stage possible.
Blue Chip Technologies Ltd. built IT365 Managed Services to address that chain—not with promises of invincibility, but with practical controls mapped to how attacks actually unfold. One partner. One package. Ongoing care.
If you'd like to talk through how your current setup would hold up against a similar scenario, we're happy to have that conversation. No pressure, no scare tactics—just an honest look at where you stand.
Get in touch:
- Visit our contact page
- Call: 1 (868) 609-2288
- WhatsApp: wa.me/18686092288
- Email: [email protected]




